Repository navigation
Releases: uehaj/sys1grep
Releases · uehaj/sys1grep
Release list
v0.5.0-next.2
What's Changed
- docs: README opens with the rename from semgrep to sys1grep (0.5.0) by @uehaj in #144
- docs: the landing page is sys1grep.js.org by @uehaj in #148
- feat: --dedup=auto|always|never; a hint when folding would pay (#143) by @uehaj in #147
- test: offline.sh's -i skipped-file pty check reads /dev/null by @uehaj in #145
- fix(--unit=function): a decorator over several lines stays with its def by @uehaj in #149
- docs: README says why sys1grep was renamed (#96) by @uehaj in #151
- feat: --rank[=jev|match] prints the results best first (#118) by @uehaj in #153
- test: skill-eval compares two sys1grep skill wordings with claude -p by @uehaj in #154
- feat: --format=plain|markdown|html shapes --rank's output; replaces --summarize-format by @uehaj in #155
- docs: CONTEXT.md names multi-step matching and its terms (#163) by @uehaj in #164
- feat: --template selects the HTML that --rank --format=html writes; a designed default (#158) by @uehaj in #159
- feat: --template=search, a search-engine style results page (#158) by @uehaj in #162
- feat: EXPRESSION --step-to EXPRESSION walks the calls from one function to another (#163) by @uehaj in #165
- fix(--step-to): review findings of #165 (names, one error wording, dash rule documented) (#163) by @uehaj in #168
- docs: mock screenshots for --serve, for inline use in #166 by @uehaj in #169
- test: dedup-eval measures --dedup=auto against never on real Jev (#152) by @uehaj in #170
Full Changelog: v0.5.0-next.1...v0.5.0-next.2
v0.5.0-next.1
What's Changed
- feat: --verbose / --dry-run print the settings a search ran with (#90) by @uehaj in #123
- feat: the rest of --summarize (#88, #76, #77, #78) by @uehaj in #124
- feat: --summarize-format=plain|markdown|html asks the summarizer for a format, plain by default (#122) by @uehaj in #127
- fix: --level and --summarize reject names every object inherits by @uehaj in #133
- ci: offline tests, gitleaks, npm pack contents by @uehaj in #134
- git sys1grep: add --cached, --untracked and ... (#50) by @uehaj in #126
- feat: -g: a span with an end gets --until, and yesterday wins over the last 24 hours (#120) by @uehaj in #135
- ci: the offline job's log names every check, and the summary counts them by @uehaj in #137
- feat: guards against generated and oversized input (#58) by @uehaj in #125
- feat: a .gz file is read decompressed, as zgrep does, and printed by its name (#68) by @uehaj in #131
- refactor: --unit=line|zero|sentence-by-jev|sentence-by-rule replaces --sentence (#140) by @uehaj in #141
- feat: --unit=function judges each function, with git grep -W's boundaries (#114) by @uehaj in #142
Full Changelog: v0.5.0-next.0...v0.5.0-next.1
v0.5.0-next.0
What's Changed
- docs: -Q explained by "The job failed." against "Did the job succeed?" by @uehaj in #72
- docs: landing page cards link to their README sections by @uehaj in #73
- docs: "Sending less" gathers what cuts cost and time; the landing card links to it by @uehaj in #74
- feat: the --dry-run summary estimates input tokens and, for TypeSafe itself, the price by @uehaj in #92
- feat: auto-scope, --summarize and a spinner (#43 #48 #46 #75 #89) by @uehaj in #82
- fix: --summarize --dedup pipes each representative once with (×N like it); over 200 KB nothing is sent (#98) by @uehaj in #102
- feat: regex matches in grep's match color, -o prints them; sentences turn bold yellow by @uehaj in #100
- feat: auto-scope --verbose names each candidate, whether it was applied, and the files it keeps (#99) by @uehaj in #103
- Drop the units no regex holds for while reading; the summary line says what its numbers are (#79 #91) by @uehaj in #101
- feat: auto-scope --verbose names the scopes each matching file got through, and the files left out (#104) by @uehaj in #106
- auto-scope runs no git when no meaning can scope (#105) by @uehaj in #107
- fix: --summarize ×N counts matching units, not lines; the size error names both counts under --dedup (#98) by @uehaj in #109
- feat: each judging request notes the scopes its lines already got through (#111) by @uehaj in #113
- feat: -g / --gitlog searches git log's commits; auto-scope becomes git log's arguments by @uehaj in #110
- Rename to sys1grep (#93) by @uehaj in #115
Full Changelog: v0.4.0...v0.5.0-next.0
v0.4.0
What's Changed
- --sentence[=jev|rules]: judge one sentence at a time, print lines like grep (-o for sentences) by @uehaj in #14
- SEMGREP_OPTS: default options from the environment by @uehaj in #24
- docs: --chunk changes results, not just speed (#9) by @uehaj in #27
- docs: replace Japanese examples outside the cross-language section with English by @uehaj in #29
- Intent grep: -Q/--question matches lines that answer a question; add -q/--quiet by @uehaj in #28
- test: offline suite against a fake Jev; npm test runs it first by @uehaj in #32
- feat: --model=ID sets the model on the command line by @uehaj in #33
- Landing page on GitHub Pages (docs/index.html) and a Pages deploy workflow by @uehaj in #34
- README: FAQ on combinations that replace --paragraph, jsonl handling and --record-separator by @uehaj in #31
- feat: --model=ID overrides SEMGREP_MODEL by @uehaj in #35
- --dedup: judge one line per template by @uehaj in #10
- -e '/regex/': match locally, prefilter, and hand captures to meanings as $ by @uehaj in #30
- feat: --sys1-model / --sys1-url / --sys1-api-key override the API settings by @uehaj in #38
- feat: git semgrep, searching tracked files like git grep by @uehaj in #36
- Fix review findings: API response checks, -q exit status, directory errors, option checks by @uehaj in #42
- docs: landing page marks regex and --dedup scenes as next release by @uehaj in #39
- docs: landing page for 0.4.0 — semgrep as the heading, new-in-0.4.0 marks by @uehaj in #51
- fix: the -r / git semgrep skip list covers .env*, credential files and id_rsa*, without case by @uehaj in #54
- mattpocock 対応: issue tracker, triage labels, domain docs for the engineering skills by @uehaj in #57
- feat: -V / --version prints the version by @uehaj in #53
- feat: -r skips what git ignores; named files and directories are searched even so by @uehaj in #55
- feat: --dry-run and --verbose show the files and requests by @uehaj in #56
- feat: --include / --exclude / --changed-within pick the files; -i asks before sending by @uehaj in #60
- chore: prepare 0.4.0 by @uehaj in #41
- fix: review of #60: -i cannot be spoofed by file names, shows read errors; dates and globs checked by @uehaj in #63
- fix: a PDF is skipped as binary; UTF-16 with a BOM is read as text by @uehaj in #62
- docs: animated SVG demo at the top of the README by @uehaj in #64
- docs: caption under the README demo links the landing page by @uehaj in #65
- docs: README shows --sentence -C 3 --color as captured by @uehaj in #66
- Landing page: git semgrep scene, and a card for the filters that cut cost by @uehaj in #37
- feat: -H / --with-filename and --no-filename (#52) by @uehaj in #67
- docs: 0.4.0 is released on 2026-09-26 by @uehaj in #71
Full Changelog: v0.3.0...v0.4.0
v0.3.1
Security fix for GHSA-vxc9-7f57-j9gx: ./.env in the current directory is no longer read. Settings come from the environment and ~/.config/semgrep/.env only. Breaking for per-project ./.env; load it explicitly with node --env-file=.env "$(command -v semgrep)" ....
Upgrade: npm install -g @uehaj/semgrep@0.3.1
v0.3.0
(first npm release since 0.2.0: also carries 0.2.2, which was tagged but never published)
Added
-z/--null-data: the unit of judgement becomes a NUL-terminated record instead of a line, so a
record may span several lines. Matching records are printed NUL-terminated too, as ingrep -z; file
names and counts stay on newlines.-nnumbers records,-A/-B/-Ccount records,--chunkcounts
records. Pairs directly withgit log -z,find -print0andxargs -0, removing the twotrcalls
previously needed to flatten a record onto one line (#6).- Other endpoints:
SEMGREP_URLandSEMGREP_MODELpoint semgrep at any TypeSafe-compatible/v1/systemone
(OpenRouter, Vercel AI Gateway, a local server). Based on #4 by @nedzen. - The summary line shows cost: the endpoint's
usage.costwhen reported, else for TypeSafe an estimate marked~.
Changed
- The API key is now
SEMGREP_API_KEY;TYPESAFE_API_KEYstill works when it is not set. The key is sent to
SEMGREP_URLas is; withSEMGREP_URLset and no key, no Authorization header is sent. - Breaking:
SEMGREP_ENVis gone../.envthen~/.config/semgrep/.envare still read. - Network errors name the endpoint's host instead of
typesafe.